ArcSight Solution Architect

8 years

0 Lacs

Posted:6 days ago| Platform: SimplyHired logo

Apply

Work Mode

On-site

Job Description

Join our Team


About this opportunity: We are looking for an experienced ArcSight Solution Architect to lead the design, implementation, and optimization of ArcSight-based security solutions. The ideal candidate will have deep expertise in SIEM (Security Information and Event Management), with hands-on experience in ArcSight architecture, deployment, and integration with various log sources and security tools. The role also includes close collaboration with cloud engineering, security operations, and compliance teams to ensure end-to-end security visibility across the GCP environment.


What will you do:


  • Analyse and understand new log source formats (syslog, flat files, APIs, JSON etc.).
  • Design and develop custom Flex Connectors, including support for JSON and non-standard log formats & deploy ArcSight Flex Connectors for custom log source integration.
  • Lead parser creation and tuning for various log sources and security technologies.
  • Collaborate with the SOC and threat intel teams to build detection use cases and correlation rules aligned with MITRE ATT&CK.
  • Integrate ArcSight with SOAR platforms for automated response, leveraging Python scripting.
  • Conduct feasibility analysis for new integrations and support parser deployment lifecycle.
  • Review parser performance, log quality, EPS optimization, and correlation tuning.
  • Document architecture, parser specifications, playbooks, and integration workflows.
  • Lead implementation projects, including installation, configuration, and tuning of ArcSight ESM, Logger, and Smart Connectors.
  • Work closely with security operations and infrastructure teams to integrate log sources and develop use cases.
  • Perform infrastructure sizing, health checks, and system performance tuning.
  • Develop and maintain documentation including solution design, implementation guides, and SOPs.
  • Provide subject matter expertise during POCs, and implementation support.


The skills you bring:


  • Bachelor in CS/IT or similar
  • 8+ years of experience in cybersecurity with at least 4+ years in ArcSight solution design and deployment.
  • Familiarity with regular expressions (regex) for parsing custom logs.
  • Experience with log onboarding, parsing, and normalization processes.
  • Log analysis (Analyst)
  • Understanding of cloud environment (GCP) & Kubernetes & docker technologies
  • Integration of different types of log sources
  • Solid understanding of - CEF (Common Event Format) ,ArcSight Event Schema and Field Mapping, Device/Product Event Categorization
  • Knowledge of Linux/Unix systems and basic scripting.
  • Experience with ArcSight content development: rules, correlation, dashboards, reports. And familiarity with ArcSight upgrades and migration planning.
  • Strong understanding of log management, threat detection, and SOC workflows.
  • Knowledge of related tools and platforms such as SIEM, SOAR, firewalls, IDS/IPS, endpoint security.
  • Scripting knowledge (e.g., Python, Shell) for automation and data parsing.
  • Excellent communication and stakeholder management skills.
  • Architect and implement end-to-end SIEM solutions using ArcSight 24* (ESM, SmartConnectors, Thub, Recon).
  • Hands-on experience in leading parser development, customization, and tuning for various log sources and third-party security technologies.
  • Integrate ArcSight with SOAR platforms for automated response, leveraging Python scripting.
  • Skilled in performing feasibility analysis and POCs for new log source integrations and managing the complete parser deployment lifecycle.


Why join Ericsson?

At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?

Click Here to find all you need to know about what our typical hiring process looks like.

Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.

Primary country and city: India (IN) ||

Req ID: 770473

Mock Interview

Practice Video Interview with JobPe AI

Start Python Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Python Skills

Practice Python coding challenges to boost your skills

Start Practicing Python Now
Ericsson logo
Ericsson

Telecommunications

Kista Stockholm

RecommendedJobs for You